Skip to content

HMAC Generator

Generate HMAC-SHA256, SHA-384, SHA-512 or SHA-1 signatures from a message and secret key.

Result

Enter a message and key, then select Generate HMAC.

Runs in your browser — nothing you enter is sent to a server.

How the HMAC Generator works

HMAC combines a secret key with a hash function to sign a message: anyone with the key can check the message wasn't changed and came from someone who knows the key. Enter the message and key (as text, hex or Base64), choose the hash, and the browser's Web Crypto API computes the HMAC — the same signature webhooks and API requests use.

Formula

HMAC = H((K ⊕ opad) ‖ H((K ⊕ ipad) ‖ message))

Examples

RFC 4231 test case 1

Key 0x0b repeated 20 times, message “Hi There”: HMAC-SHA256 = b0344c61d8db38535ca8afceaf0bf12b881dc200c9833da726e9376c2e32cff7.

Verifying a webhook

Compute the HMAC of the raw request body with your webhook secret and compare it with the signature header.

Frequently asked questions

Is HMAC encryption?

No — it proves integrity and authenticity; the message itself stays readable.

Which algorithm should I use?

HMAC-SHA256 unless a service specifies otherwise. HMAC-SHA1 is still safe as an HMAC but best avoided in new designs.

Why doesn't my result match?

Check the key format (text vs hex vs Base64), extra spaces or newlines in the message, and hex vs Base64 output.

Hash Generator

Generate MD5, SHA-1, SHA-256, SHA-384 and SHA-512 hashes of text or files, and check a checksum.

Security Tools

JWT Decoder

Decode a JSON Web Token to read its header and claims, with expiry times in plain language.

Developer Tools

Base64 Encoder & Decoder

Encode text to Base64 or decode Base64 to text, with full Unicode support and URL-safe output.

Developer Tools

TOTP Code Generator (2FA)

Generate time-based one-time passwords from a 2FA secret or otpauth link, like an authenticator app.

Security Tools